# Exercise: Audit Your Current Metrics To begin addressing these challenges, conduct an assessment of your existing security metrics and their business relevance: - List all security metrics currently reported to executives and the board - For each metric, identify whether it measures an activity, outcome, or impact - Map each metric to specific business objectives it supports (if any) - Rate each metric's effectiveness in communicating business value (low, medium, high) - Identify which metrics executives reference or ask questions about - Document any requests from business leaders for specific security information This exercise will likely reveal significant gaps in your current measurement approach. Many organizations discover that their metrics heavily favor technical activities with minimal connection to business priorities. These gaps represent opportunities to develop more business-aligned security measurements. When evaluating metrics' alignment with business objectives, consider both explicit connections (such as metrics directly tied to corporate goals) and implicit relationships (such as how security activities indirectly support business initiatives). This analysis provides the foundation for developing more business-relevant security metrics. *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)